Hrm, couldn't get to page 3. Guess he needs a school for scaling static content delivery.
works ok for me, what error do you get?
The school for sysadmins who can’t timesync good
11–20 of 33 posts
Re: The school for sysadmins who can’t timesync good
#12A large number of them were out-of-date and at their end-of-life. HP was charging a super premium for keeping them in support beyond their normal end-of-life period... some reseller pointed this out as a justification for why it would be cheaper to replace them than to keep them in support. It back-fired: QLD police just took them out of support without replacing the hardware. State-level critical infrastructure running on obsolete equipment with no vendor support....
Re: The school for sysadmins who can’t timesync good
#13Earlier quoted context omitted.
I cheat and have an authoritative NTP server locally and then override dns for pool.ntp.org and friends. Then at least if I’m off we’re all off together.
For bonus points, hook up a GPS with a PPS output to the local one so it's stratum 1.
How big is that unmeasured error?
Re: The school for sysadmins who can’t timesync good
#14Part 1 - The Problem with NTP: https://web.archive.org/web/20210627035347/https://libertysy...
Part 2 - How NTP Works: https://web.archive.org/web/20210627035910/https://libertysy...
Part 3 - Installation and Configuration: https://web.archive.org/web/20210308233351/https://libertysy...
Part 4 - Monitoring and Troubleshooting: https://web.archive.org/web/20210308233515mp_/https://libert...
Part 5 - Myths, Misconceptions, and Best Practices: https://web.archive.org/web/20210308232954mp_/https://libert...
Re: The school for sysadmins who can’t timesync good
#15Nice comprehensive series but couldn't get to page 4 -site timed out. On the windows side of things, I'm more familiar with "w32tm" and "net time." My time sync post has the highest amount of views on my site from people googling "how to set time clock on domain" so their cell phones match their computers at work. Would be interesting to see how the windows protocols differ from nix.
The Win32 daemon only provides coarse time adjustment. Basically doing an ntpdate to adjust the clocks once per day or so. Good enough for domain logins, but a couple orders of magnitude worse than the regular NTP protocol. Of course on Linux most of the arcane details of the ntp daemon aren't relevant because most distros end up running SystemD with timesyncd instead. I discovered this when all of my T1 time sources…
True in XP (it was a crappy SNTP implementation), but it was rehauled significantly in Windows 10/Server 2016 and above because of Azure requirements. It can now guarantee accuracy within 1 second at all times and even higher when the NTP server is local (https://docs.microsoft.com/en-us/windows-server/networking/w...)
Re: The school for sysadmins who can’t timesync good
#16Re: The school for sysadmins who can’t timesync good
#17Re: The school for sysadmins who can’t timesync good
#18Most of the time none of that matters and you can just install chronie and point it to whatever.pool.ntp.org and you’re off to the races. But boy does it suck when you have to to know.
Re: The school for sysadmins who can’t timesync good
#19Re: The school for sysadmins who can’t timesync good
#20Oh dear... I've been triggered by that reference to the HP-UX boxes at Queensland police in the early 2000s... yes, it was as bad as can be imagined... no, actually, it was worse. A large number of them were out-of-date and at their end-of-life. HP was charging a super premium for keeping them in support beyond their normal end-of-life period... some reseller pointed this out as a justification for why it would be ch…
I inherited an "enterprise environment" to look after that had attempts to talk to on prem NTP services via VPN, but that had failed over time. Cybersec had closed the route without notice and the environment eventually drifted out of sync and was completely unable to get updates. It hadn't had any updates for 3 years. There were still other elements of the VPN that could talk to parts of both networks used between two big agencies supported. That system was classified as sensitive. Also, the firewall hadn't had a definitions review in 4 years. .Net Core alpha release was being used.
Fortunately I was able to nuke the whole thing because of the low number of users.